CVE-2023-0174: WP VR < 8.2.7 - Contributor+ Stored XSS
Published Feb 6, 2023
·Updated
The WP VR WordPress plugin before 8.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Affected Software
1 affected component
Rextheme Wp Vr Wordpress<8.2.7
Event History
Feb 6, 2023
CVE Published
via MITRE·07:59 PM
Data Sourced
via MITRE·07:59 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the CVE ID?
The CVE ID is CVE-2023-0174.
2
What is the vulnerability in the WP VR WordPress plugin?
The vulnerability in the WP VR WordPress plugin is a Stored Cross-Site Scripting (XSS) vulnerability.
3
How does the WP VR WordPress plugin vulnerability impact users?
The vulnerability allows users with the contributor role and above to perform Stored Cross-Site Scripting (XSS) attacks.
4
What is the severity of the WP VR WordPress plugin vulnerability?
The severity of the WP VR WordPress plugin vulnerability is medium with a CVSS score of 5.4.
5
How can I fix the WP VR WordPress plugin vulnerability?
To fix the WP VR WordPress plugin vulnerability, update to version 8.2.7 or later.